Description
AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause the “Incomplete List of Disallowed Inputs” by local access. Successful exploitation of this vulnerability may lead to arbitrary code execution and impact system Confidentiality, Integrity, and Availability.
Published: 2026-09-08
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution
Action: Patch
AI Analysis

Impact

A vulnerability in AMI AptioV BIOS allows a privileged local user to trigger an "Incomplete List of Disallowed Inputs" condition. Successful exploitation can lead to arbitrary code execution, directly compromising the confidentiality, integrity, and availability of the affected system. The issue stems from a flaw in the handling of inputs to the BDS module, classified as CWE‑184. The impact is the ability for a local attacker to take full control of the machine’s firmware and subsequently the operating system.

Affected Systems

The vulnerability affects systems running AMI AptioV BIOS firmware. No specific versions are listed in the advisory, so any installation of AptioV may be susceptible until a vendor update is applied. System owners should verify their BIOS version against the latest AMI release notes.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. The EPSS score is currently unavailable, but the lack of a KEV listing does not diminish the risk to privileged users with local access. Based on the description, it is inferred that a local attacker who can interact with the BIOS—such as a user with physical access or one who has compromised the host—can exploit the flaw. The exploit requires local privilege but does not require network connectivity or elevated OS permissions, making it particularly dangerous in environments where device access is not tightly controlled.

Generated by OpenCVE AI on September 8, 2026 at 16:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install the latest AMI AptioV firmware update that addresses the BDS module bypass issue.
  • Apply a strong BIOS administrator password and enable BIOS lockout to restrict local privileged access.
  • Configure Secure Boot and, if possible, disable the BDS module or other unnecessary boot features to reduce the attack surface.
  • Review the AMI security advisory for any platform‑specific configuration steps.

Generated by OpenCVE AI on September 8, 2026 at 16:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Ami
Ami aptio V
Vendors & Products Ami
Ami aptio V

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause the “Incomplete List of Disallowed Inputs” by local access. Successful exploitation of this vulnerability may lead to arbitrary code execution and impact system Confidentiality, Integrity, and Availability.
Title BDS Module Bypass Secure Boot Advisory
Weaknesses CWE-184
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: AMI

Published:

Updated: 2026-09-08T15:22:30.375Z

Reserved: 2026-03-17T22:18:45.992Z

Link: CVE-2026-33197

cve-icon Vulnrichment

Updated: 2026-09-08T15:22:27.365Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T15:18:42.960

Modified: 2026-09-08T16:18:08.077

Link: CVE-2026-33197

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:30:17Z

Weaknesses
  • CWE-184

    Incomplete List of Disallowed Inputs